Results 1 to 2 of 2
  1. #1
    Vallerius's Avatar
    Vallerius is offline Independent Reporter
    Join Date
    August 2006
    Location
    St. Louis, Missouri, USA
    Posts
    85
    Thanks
    0
    Thanked 1 Time in 1 Post

    Default Hackers demanding ransom from online gambling sites.....?

    Hi y'all, and happy Halloween.

    Here's an article somebody suggested I write to the portal webmasters about: http://www.cbc.ca/technology<wbr>/story/2006/10/28/online<wbr>-gambling.html

    I think that gravity and threat of hackers has been a bit exaggerated in this article, but yeah, hackers are fact of life that online gambling companies-- like all high-tech companies-- have to deal with.

    Online gambling companies first starting reporting that their sites were being brought down by hackers in the fall of 2003. The hackers were using a technique called distributed denial of service (DDoS) attacks. Essentially they had been able to infect a massive number of computers with trojan horse viruses that lie dormant until called into action. The hackers could then command their networks of thousands of trojans to use the infected computers to bombard online gambling sites with so much incoming data that the sites became unable to transmit outgoing data, hence the term "denial of service", because customers are denied access to the site. Hackers can sustain such an attack indefinitely.

    DDoS attacks against more than a dozen Internet sportsbooks were documented in September 2003. In most cases the hackers would first send an e-mail to the sportsbook operator threatening to bring their website down if the operator did not wire a large sum of money (around $40,000-$60,000) to them. The e-mails were always written in badly broken English, and they always requested that the ransom money be wired to a some location in Russia. The e-mails would be followed by a DDoS assault that would bring the site down until the operator could install a solution to overcome it or pay off the extortion demand. The operators suspected that a single small network of Russian hackers was responsible for all the attacks that struck the industry in late 2003 and early 2004.

    DDoS attacks were hardly a new thing at the time, they have probably been around as long as the Internet itself, but this was the first time that an entire industry had faced such a legitimate threat. The nature of online gambling businesses makes them a particulary appealing target. They have lots of cash on hand and it is especially important that their websites be up and running at all times-- especailly during a major sporting event. For example, many sites were threatened and attacked in the days and hours leading up to Super Bowl Sunday in January 2004, the biggest betting day of the year in North America and a time when sites cannot afford to be down for a single second.

    It was suspected that at least a few companies might have chosen to pay off the extortion demands. Although several companies did report attacks to police authorities, it is suspected that far more were attacked than actually reported it. For some there was reluctance to report the problem because they suspected (and probably rightly so) that they would lose customers if they were to reveal that their systems were susceptible to hackers.

    It was only a matter of months however until most online gambling companies had sufficient secuirity solutions in place to mitigate DDoS attacks, but for those few months DDoS attacks were the hottest issue in the industry. All of the following sites are known to have been targeted by a DDoS attack of some degree in 2003 and 2004: William Hill, Coral, Paddy Power, Totalbet, IG Index, Sporting Index, Blue Square, Skybet, Betdaq, Coral, UKbetting, Bet365, Stanley Racing, Sportingbet.com, Centrebet, Betfair, Victor Chandler, Capital Sports, Ladbrokes, Sporting Options, Totalbet, Sportinglife.com, VIP, Bet19, Gameday, Superbook, BetCRIS, BetVSI, Virtual Bookmaker, MVP, V-Wager and Players Superbook.

    In July of 2004 Britain's National Hi-Tech Crime Unit (NHTCU) and Russia's Ministry of Internal Affairs announced that they had aprehended three men in Russia-- aged 21, 22 and 24-- whom they suspected were responsible for the attacks against online gambling companies. Although a broaders network of hackers was suspected, these were the three men who coordinated everything and laundered the money. All three of them were consequently prosecuted, found guilty and sentenced.

    So yeah, DDoS attacks were definitely a threat that demanded attention once upon a time, but most of the industry is now very aware of their threat and have installed sufficient security systems. I would be very suprised today to learn of an attack that was strong enough to bring a legitimate site down.

    --

    I also want to show you guys a new daily article that the other Casino City writers and I have just begun working on. Each day we scour the Internet and find news that is important but that we don't quite have the time to cover. So we are collecting interesting articles from around the Internet each day and providing links to them. I think the same link should work every day.... but I might be wrong. I guess I'll know tomorrow.

    Here it is: http://www.rgtonline.com/Article.cfm...yName=Featured

  2. #2
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,972
    Thanks
    4,536
    Thanked 9,290 Times in 5,977 Posts

    Default

    The threat of DDos attacks was very real, both then and now.

    I personally witnessed (and helped combat) one of these attacks. (by the way the domain which will remain not spoken, was not in the above list)

    The attack I saw was very severe, and yes it was during the time frame mentioned so there were less solutions in place to combat them than there is now.

    To think that attacks can not have a severe threat now is not forward thinking enough(IMO). During the attack I witnessed, the hackers ended up throwing 40 meg packets at the site. Since we also called in consultants from the NOC itself, the pipe leading to the servers was opened wide to allow all bandwidth needed.

    The attack actually continued, and in fact increased to the point it almost filled an OC 48 and was actually choking the router for the NOC.

    I agree that most sites are better equipped to handle these kind of attacks, but there are plenty of bot networks out on the internet that these types of attacks are still a very real threat, and will continue to be so for a long time.

    Rick
    Universal4
    Gambling World Online Roulette Online Blackjack Live Online Games Sports Betting Horse Racing
    Casino Affiliate Programs
    Hosting and Domain Names
    Gambling Industry Association
    GPWA Moderation by Me and My Big Bad Security Self
    If an affiliate program is not small affiliate friendly (especially small US Affiliate), then they are NOT Affiliate Friendly!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •